PatchSiren

chamilo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM chamilo CVE published 2026-09-11

CVE-2026-82535

CVE-2026-82535 is a stored cross-site scripting vulnerability in Chamilo LMS before 1.11.42 and 3.0.0. Unauthenticated attackers can inject malicious script payloads into survey answers, which are then rendered in reporting views, potentially executing arbitrary scripts in the browser sessions of teachers or administrators. This vulnerability allows attackers to bypass authorization checks in the survey s [truncated]